VYPR
Medium severity5.5NVD Advisory· Published Sep 1, 2023· Updated Jun 17, 2026

CVE-2023-4378

CVE-2023-4378

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A malicious Maintainer can, under specific circumstances, leak the sentry token by changing the configured URL in the Sentry error tracking settings page. This was as a result of an incomplete fix for CVE-2022-4365.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • GitLab Inc./GitLabv56 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 11.8
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.8.0,<16.1.5
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.8.0,<16.1.5
    • cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:community:*:*:*
    • cpe:2.3:a:gitlab:gitlab:16.3.0:*:*:*:enterprise:*:*:*
    • (no CPE)range: starting from 11.8 before 16.1.5, starting from 16.2 before 16.2.5, starting from 16.3 before 16.3.1
  • Range: starting from 11.8 before 16.1.5, starting from 16.2 before 16.2.5, starting from 16.3 before 16.3.1
  • osv-coords
    Range: >= 11.8.0, < 16.1.5

Patches

Vulnerability mechanics

References

2

News mentions

1